Vendor CVEs
Samsung Mobile
All CVEs
2,312 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-21054 | Med | 0.26 | 4.0 | 0.00 | Oct 10, 2025 | Out-of-bounds read in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to potentially access out-of-bounds memory. | ||
| CVE-2025-21053 | Med | 0.26 | 4.0 | 0.00 | Oct 10, 2025 | Out-of-bounds write in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory corruption. | ||
| CVE-2025-21052 | Med | 0.26 | 4.0 | 0.00 | Oct 10, 2025 | Out-of-bounds write under specific condition in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory corruption. | ||
| CVE-2025-21051 | Med | 0.26 | 4.0 | 0.00 | Oct 10, 2025 | Out-of-bounds write in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to write out-of-bounds memory. | ||
| CVE-2025-21045 | Med | 0.26 | 4.0 | 0.00 | Oct 10, 2025 | Insecure storage of sensitive information in Galaxy Watch prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. | ||
| CVE-2025-21034 | Med | 0.26 | 4.0 | 0.00 | Sep 3, 2025 | Out-of-bounds write in libsavsvc.so prior to SMR Sep-2025 Release 1 allows local attackers to potentially execute arbitrary code. | ||
| CVE-2025-21033 | Med | 0.26 | 4.0 | 0.00 | Sep 3, 2025 | Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive information. | ||
| CVE-2025-21029 | Med | 0.26 | 4.0 | 0.00 | Sep 3, 2025 | Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows local attackers to send arbitrary replies to messages from the cover display. | ||
| CVE-2025-21026 | Med | 0.26 | 4.0 | 0.00 | Sep 3, 2025 | Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call. | ||
| CVE-2023-21471 | Med | 0.26 | 4.0 | 0.00 | Sep 3, 2025 | Improper access control vulnerability in SemClipboard prior to SMR Apr-2023 Release 1 allows attackers to read arbitrary files with system permission. | ||
| CVE-2023-21470 | Med | 0.26 | 4.0 | 0.00 | Sep 3, 2025 | Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.NETWORK_LOCATION action. | ||
| CVE-2023-21469 | Med | 0.26 | 4.0 | 0.00 | Sep 3, 2025 | Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.GEOFENCE action. | ||
| CVE-2025-21015 | Med | 0.26 | 4.0 | 0.00 | Aug 6, 2025 | Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege. | ||
| CVE-2025-20990 | Med | 0.26 | 4.0 | 0.00 | Aug 6, 2025 | Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access device identifier. | ||
| CVE-2025-21003 | Med | 0.26 | 4.0 | 0.00 | Jul 8, 2025 | Insecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows local attackers to access sensitive information. | ||
| CVE-2025-20993 | Med | 0.26 | 4.0 | 0.00 | Jun 4, 2025 | Out-of-bounds write in libsecimaging.camera.samsung.so prior to SMR Jun-2025 Release 1 allows local attackers to write out-of-bounds memory. | ||
| CVE-2025-20992 | Med | 0.26 | 4.0 | 0.00 | Jun 4, 2025 | Out-of-bound read in libsecimaging.camera.samsung.so prior to SMR Feb-2025 Release 1 allows local attackers to read out-of-bounds memory. | ||
| CVE-2025-20991 | Med | 0.26 | 4.0 | 0.00 | Jun 4, 2025 | Improper export of Android application components in Bluetooth prior to SMR Jun-2025 Release 1 allows local attackers to make devices discoverable. | ||
| CVE-2025-20980 | Med | 0.26 | 4.0 | 0.00 | May 7, 2025 | Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption. | ||
| CVE-2025-20962 | Med | 0.26 | 4.0 | 0.00 | May 7, 2025 | Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position. | ||
| CVE-2025-20960 | Med | 0.26 | 4.0 | 0.00 | May 7, 2025 | Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api. | ||
| CVE-2025-20950 | Med | 0.26 | 4.0 | 0.00 | Apr 8, 2025 | Use of implicit intent for sensitive communication in SamsungNotes prior to version 4.4.26.45 allows local attackers to access sensitive information. | ||
| CVE-2025-20945 | Med | 0.26 | 4.0 | 0.00 | Apr 8, 2025 | Improper access control in Galaxy Watch prior to SMR Apr-2025 Release 1 allows local attackers to access sensitive information of Galaxy watch. | ||
| CVE-2025-20940 | Med | 0.26 | 4.0 | 0.00 | Apr 8, 2025 | Improper handling of insufficient permission in Samsung Device Health Manager Service prior to SMR Apr-2025 Release 1 allows local attackers to access provider in SDMHS. | ||
| CVE-2025-20923 | Med | 0.26 | 4.0 | 0.00 | Mar 6, 2025 | Improper access control in Galaxy Wearable prior to version 2.2.61.24112961 allows local attackers to launch arbitrary activity with Galaxy Wearable privilege. | ||
| CVE-2025-20909 | Med | 0.26 | 4.0 | 0.00 | Mar 6, 2025 | Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to access sensitive information. | ||
| CVE-2025-20899 | Med | 0.26 | 4.0 | 0.00 | Feb 4, 2025 | Improper access control in PushNotification prior to version 13.0.00.15 in Android 12, 14.0.00.7 in Android 13, and 15.1.00.5 in Android 14 allows local attackers to access sensitive information. | ||
| CVE-2025-20896 | Med | 0.26 | 4.0 | 0.00 | Feb 4, 2025 | Use of implicit intent for sensitive communication in EasySetup prior to version 11.1.18 allows local attackers to access sensitive information. | ||
| CVE-2024-49416 | Med | 0.26 | 4.0 | 0.00 | Dec 3, 2024 | Use of implicit intent for sensitive communication in SmartThings prior to version 1.8.21 allows local attackers to get sensitive information. | ||
| CVE-2024-34680 | Med | 0.26 | 4.0 | 0.00 | Nov 6, 2024 | Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allows local attackers to get sensitive information. | ||
| CVE-2024-34679 | Med | 0.26 | 4.0 | 0.00 | Nov 6, 2024 | Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone privilege. | ||
| CVE-2024-34677 | Med | 0.26 | 4.0 | 0.00 | Nov 6, 2024 | Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious apps appear as legitimate. | ||
| CVE-2024-34670 | Med | 0.26 | 4.0 | 0.00 | Oct 8, 2024 | Use of implicit intent for sensitive communication in Sound Assistant prior to version 6.1.0.9 allows local attackers to get sensitive information. | ||
| CVE-2024-34658 | Med | 0.26 | 4.0 | 0.00 | Sep 4, 2024 | Out-of-bounds read in Samsung Notes allows local attackers to bypass ASLR. | ||
| CVE-2024-34652 | Med | 0.26 | 4.0 | 0.00 | Sep 4, 2024 | Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage. | ||
| CVE-2024-34650 | Med | 0.26 | 4.0 | 0.00 | Sep 4, 2024 | Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel. | ||
| CVE-2024-34647 | Med | 0.26 | 4.0 | 0.00 | Sep 4, 2024 | Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license. | ||
| CVE-2024-34636 | Med | 0.26 | 4.0 | 0.00 | Aug 7, 2024 | Use of implicit intent for sensitive communication in Samsung Email prior to version 6.1.94.2 allows local attackers to get sensitive information. | ||
| CVE-2024-34635 | Med | 0.26 | 4.0 | 0.00 | Aug 7, 2024 | Out-of-bounds read in parsing textbox object in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory. | ||
| CVE-2024-34634 | Med | 0.26 | 4.0 | 0.00 | Aug 7, 2024 | Out-of-bounds read in parsing connected object list in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory. | ||
| CVE-2024-34633 | Med | 0.26 | 4.0 | 0.00 | Aug 7, 2024 | Out-of-bounds read in parsing object header in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory. | ||
| CVE-2024-34632 | Med | 0.26 | 4.0 | 0.00 | Aug 7, 2024 | Out-of-bounds read in uuid parsing in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory. | ||
| CVE-2024-34618 | Med | 0.26 | 4.0 | 0.00 | Aug 7, 2024 | Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to access cell related information. | ||
| CVE-2024-34617 | Med | 0.26 | 4.0 | 0.00 | Aug 7, 2024 | Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application. | ||
| CVE-2024-34613 | Med | 0.26 | 4.0 | 0.00 | Aug 7, 2024 | Improper access control in Galaxy Watch prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive information of Galaxy watch. | ||
| CVE-2024-34603 | Med | 0.26 | 4.0 | 0.00 | Jul 8, 2024 | Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to access location data. | ||
| CVE-2024-34599 | Med | 0.26 | 4.0 | 0.00 | Jul 2, 2024 | Improper input validation in Tips prior to version 6.2.9.4 in Android 14 allows local attacker to send broadcast with Tips' privilege. | ||
| CVE-2024-34583 | Med | 0.26 | 4.0 | 0.00 | Jul 2, 2024 | Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier. | ||
| CVE-2024-20900 | Med | 0.26 | 4.0 | 0.00 | Jul 2, 2024 | Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authentication. | ||
| CVE-2024-20899 | Med | 0.26 | 4.0 | 0.00 | Jul 2, 2024 | Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. |
- risk 0.26cvss 4.0epss 0.00
Out-of-bounds read in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to potentially access out-of-bounds memory.
- risk 0.26cvss 4.0epss 0.00
Out-of-bounds write in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory corruption.
- risk 0.26cvss 4.0epss 0.00
Out-of-bounds write under specific condition in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory corruption.
- risk 0.26cvss 4.0epss 0.00
Out-of-bounds write in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to write out-of-bounds memory.
- risk 0.26cvss 4.0epss 0.00
Insecure storage of sensitive information in Galaxy Watch prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information.
- risk 0.26cvss 4.0epss 0.00
Out-of-bounds write in libsavsvc.so prior to SMR Sep-2025 Release 1 allows local attackers to potentially execute arbitrary code.
- risk 0.26cvss 4.0epss 0.00
Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive information.
- risk 0.26cvss 4.0epss 0.00
Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows local attackers to send arbitrary replies to messages from the cover display.
- risk 0.26cvss 4.0epss 0.00
Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in SemClipboard prior to SMR Apr-2023 Release 1 allows attackers to read arbitrary files with system permission.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.NETWORK_LOCATION action.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.GEOFENCE action.
- risk 0.26cvss 4.0epss 0.00
Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.
- risk 0.26cvss 4.0epss 0.00
Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access device identifier.
- risk 0.26cvss 4.0epss 0.00
Insecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows local attackers to access sensitive information.
- risk 0.26cvss 4.0epss 0.00
Out-of-bounds write in libsecimaging.camera.samsung.so prior to SMR Jun-2025 Release 1 allows local attackers to write out-of-bounds memory.
- risk 0.26cvss 4.0epss 0.00
Out-of-bound read in libsecimaging.camera.samsung.so prior to SMR Feb-2025 Release 1 allows local attackers to read out-of-bounds memory.
- risk 0.26cvss 4.0epss 0.00
Improper export of Android application components in Bluetooth prior to SMR Jun-2025 Release 1 allows local attackers to make devices discoverable.
- risk 0.26cvss 4.0epss 0.00
Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption.
- risk 0.26cvss 4.0epss 0.00
Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position.
- risk 0.26cvss 4.0epss 0.00
Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api.
- risk 0.26cvss 4.0epss 0.00
Use of implicit intent for sensitive communication in SamsungNotes prior to version 4.4.26.45 allows local attackers to access sensitive information.
- risk 0.26cvss 4.0epss 0.00
Improper access control in Galaxy Watch prior to SMR Apr-2025 Release 1 allows local attackers to access sensitive information of Galaxy watch.
- risk 0.26cvss 4.0epss 0.00
Improper handling of insufficient permission in Samsung Device Health Manager Service prior to SMR Apr-2025 Release 1 allows local attackers to access provider in SDMHS.
- risk 0.26cvss 4.0epss 0.00
Improper access control in Galaxy Wearable prior to version 2.2.61.24112961 allows local attackers to launch arbitrary activity with Galaxy Wearable privilege.
- risk 0.26cvss 4.0epss 0.00
Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to access sensitive information.
- risk 0.26cvss 4.0epss 0.00
Improper access control in PushNotification prior to version 13.0.00.15 in Android 12, 14.0.00.7 in Android 13, and 15.1.00.5 in Android 14 allows local attackers to access sensitive information.
- risk 0.26cvss 4.0epss 0.00
Use of implicit intent for sensitive communication in EasySetup prior to version 11.1.18 allows local attackers to access sensitive information.
- risk 0.26cvss 4.0epss 0.00
Use of implicit intent for sensitive communication in SmartThings prior to version 1.8.21 allows local attackers to get sensitive information.
- risk 0.26cvss 4.0epss 0.00
Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allows local attackers to get sensitive information.
- risk 0.26cvss 4.0epss 0.00
Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone privilege.
- risk 0.26cvss 4.0epss 0.00
Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious apps appear as legitimate.
- risk 0.26cvss 4.0epss 0.00
Use of implicit intent for sensitive communication in Sound Assistant prior to version 6.1.0.9 allows local attackers to get sensitive information.
- risk 0.26cvss 4.0epss 0.00
Out-of-bounds read in Samsung Notes allows local attackers to bypass ASLR.
- risk 0.26cvss 4.0epss 0.00
Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.
- risk 0.26cvss 4.0epss 0.00
Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.
- risk 0.26cvss 4.0epss 0.00
Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license.
- risk 0.26cvss 4.0epss 0.00
Use of implicit intent for sensitive communication in Samsung Email prior to version 6.1.94.2 allows local attackers to get sensitive information.
- risk 0.26cvss 4.0epss 0.00
Out-of-bounds read in parsing textbox object in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.
- risk 0.26cvss 4.0epss 0.00
Out-of-bounds read in parsing connected object list in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.
- risk 0.26cvss 4.0epss 0.00
Out-of-bounds read in parsing object header in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.
- risk 0.26cvss 4.0epss 0.00
Out-of-bounds read in uuid parsing in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.
- risk 0.26cvss 4.0epss 0.00
Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to access cell related information.
- risk 0.26cvss 4.0epss 0.00
Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application.
- risk 0.26cvss 4.0epss 0.00
Improper access control in Galaxy Watch prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive information of Galaxy watch.
- risk 0.26cvss 4.0epss 0.00
Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to access location data.
- risk 0.26cvss 4.0epss 0.00
Improper input validation in Tips prior to version 6.2.9.4 in Android 14 allows local attacker to send broadcast with Tips' privilege.
- risk 0.26cvss 4.0epss 0.00
Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier.
- risk 0.26cvss 4.0epss 0.00
Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authentication.
- risk 0.26cvss 4.0epss 0.00
Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.
Page 38 of 47